One Platform for CCPA Risk Assessments

Scope all five CCPA triggers, run the assessments, and keep every response, finding, and sign-off filing-ready for April 2028. Your rules, your team in control.

AriseHealth logoOE logo2020INC logoThe Paak logoEphicient logoToogether logo

California’s final rules were approved on September 23, 2025. Tap any milestone below for the detail.

Rulemaking Risk assessments ADMT Cyber audits

The California Privacy Protection Agency formally proposes final rules covering ADMT, privacy risk assessments, and cybersecurity audits — closing a nearly five-year rulemaking process.

California’s Office of Administrative Law approves the final regulations, locking in every compliance date below.

Businesses whose processing presents a “significant risk” to privacy — selling or sharing data, processing sensitive data, ADMT, profiling, or training AI — must conduct and document risk assessments before processing continues.

Risk assessment duties are already live and ADMT is six months out. This is the window to inventory in-scope systems, confirm which of the five triggers apply, and stand up a repeatable assessment process before the ADMT rules bite.

Businesses using automated decision-making technology for significant decisions — lending, housing, employment, education, or healthcare — must give consumers pre-use notice, honor opt-outs, and respond to access requests.

Any processing underway during 2026–2027 must have a completed risk assessment on file — the deadline that determines what goes in the first regulator filing.

Risk assessments conducted in 2026–2027 must be submitted to the CPPA, signed off by an executive. The same date is the first cybersecurity audit certification deadline for businesses over $100M in annual revenue.

Businesses with $50–100M in revenue submit their first independent cybersecurity audit certification to the CPPA.

Businesses under $50M in revenue submit their first cybersecurity audit certification. From here, certifications are annual and risk assessments are reviewed at least every three years.

Dates reflect the CCPA/CPRA regulations approved by California’s OAL on September 23, 2025. This timeline is a planning aid, not legal advice — applicability and deadlines for your business are a judgment for your counsel.

Regulator-ready by April 2028
Every assessment is mapped to the requirement it addresses, with responses, findings, and sign-offs attached.

When the filing date comes, you export; when an executive asks where things stand, the dashboard answers, by entity and by trigger.
Assessments that get completed

Conditional questionnaires show respondents only what applies to them, intake runs through tools like Jira, and approvals happen from email.

Complyance AI reads the responses and flags findings, so your team reviews a prioritized list, not a wall of free text.
Five triggers, scoped before you start

Selling/sharing data, sensitive personal information, ADMT, profiling, and AI training each require their own assessment, and companies hit three without realizing it, including B2B.

Complyance scopes all five against your actual operations, so nothing is missed and nothing is over-built.
CCPA Risk Assessment Scope Checker

Which of the five triggers apply to you?

Six questions, two minutes. See which CCPA risk assessment triggers your operations hit and what the April 2028 filing means for you.

Your result

This checker is a scoping aid, not legal advice. Whether a specific activity triggers a CCPA risk assessment is a judgment for your counsel.

Frequently asked questions